SaMD is software that performs one or more medical purposes without being part of a medical device with a hardware component. The term originates from IMDRF and is used by regulators such as the US FDA. In the EU, the broader concept of Medical Device Software (MDSW) can include both standalone software (SaMD) and software that is integral to, drives, or influences a medical device, as addressed in MDCG 2019-11 Rev.1.

Software as a medical device (SaMD) and software in a medical device (SiMD) play an increasingly critical role in modern healthcare, supporting diagnosis, treatment and monitoring across a wide range of digital health applications. As these technologies evolve, manufacturers must navigate regulatory requirements for safety, performance and quality. This includes the requirements under the EU Medical Device Regulation (MDR) and In Vitro Diagnostic Medical Devices Regulation (IVDR), as applicable, as well as appropriate quality management system (QMS) requirements.
We provide services to help you navigate the regulatory requirements for SaMD and SiMD, from regulatory conformity assessment to QMS certification and auditing, supporting market access across global markets.
Ensure your SaMD and SiMD products meet all regulatory requirements
- Achieve market access
Certify your SaMD and SiMD products to meet EU, UK and international regulatory requirements.
- Ensure regulatory compliance
Align your software with MDR, UKCA, MDSAP and other applicable medical device regulations.
- Certify your quality management system
Gain ISO 13485 certification to demonstrate a robust, compliant QMS.
- Streamline your audits
Our integrated and combined audits save you time and resources, with remote audit options available for eligible SaMD organizations.
- Access dedicated support
Work with an account management team dedicated to your certification project.
- Benefit from global expertise
Draw on our worldwide network and local market knowledge, wherever you operate.
Discover our services for SaMD and SiMD
- ISO 13485 quality management system certification
Certify your quality management system against the international standard for medical device manufacturers.
- EU Notified Body services
Support CE marking of your medical device software through conformity assessment under the EU MDR or IVDR, as applicable.
- UK Approved Body services
Support UKCA marking and access to the Great Britain market through conformity assessment under applicable UK medical device regulation.
- MDSAP auditing
Streamline your quality system audits across multiple markets through the Medical Device Single Audit Program.
Why SGS?
As a global leader in testing, inspection and certification, we bring extensive medical device regulatory and technical expertise to support software manufacturers throughout the product lifecycle. Through our accredited certification bodies, EU Notified Body and UK Approved Body services, we support quality management system certification, conformity assessment and access to key global markets.
Our global network combines regulatory expertise with local market knowledge, helping manufacturers navigate the evolving requirements for medical device software, including software lifecycle, cybersecurity, clinical evidence and emerging AI-enabled technologies.

FAQs
SaMD is standalone software that is not part of a medical device with a hardware component, and performs a medical purpose on its own. SiMD is software that operates as an integral part of a medical device and is necessary for the device to achieve its intended medical purpose.
Typical SiMD examples include firmware or other software that controls or enables the operation of a medical device, such as software controlling X-ray generation in a CT scanner or therapy delivery in an infusion pump. Typical SaMD examples include DICOM medical image viewing software intended for diagnostic interpretation or diabetes management software intended to support treatment decisions. SaMD may run on general-purpose computing platforms, such as smartphones, tablets, or computers.
Medical device software must comply with the EU MDR or IVDR, as applicable, as well as other applicable EU legislation. Manufacturers must determine the software's qualification and classification, meet applicable quality management system and technical documentation requirements, complete required registrations, and follow the appropriate conformity assessment route. Depending on the software's classification, conformity assessment by a notified body may be required before CE marking and placing the device on the EU market.
Requirements vary by jurisdiction and may include device qualification and classification, an appropriate quality management system (QMS), product authorization or licensing, establishment and device registration, labeling, and post-market obligations. The Medical Device Single Audit Program (MDSAP) can streamline QMS audits across participating jurisdictions, but it does not replace jurisdiction-specific product authorization or licensing requirements.
Under IEC 62304, software safety classification is determined based on whether the software system can contribute to a hazardous situation and the severity of the resulting possible harm, taking into account applicable risk control measures external to the software system. The classification must be supported by documented risk analysis. Software safety classification is separate from the device’s regulatory classification and determines the applicable level of rigor for software development and maintenance lifecycle processes and associated documentation.
Yes. Cybersecurity must be addressed throughout the medical device lifecycle and is an important consideration for regulatory authorization or certification in major markets. In the EU, applicable MDR/IVDR requirements, including relevant General Safety and Performance Requirements (GSPRs), are supported by cybersecurity guidance such as MDCG 2019-16 Rev.1. In the US, FDA cybersecurity guidance applies as appropriate, with additional statutory requirements under Section 524B of the FD&C Act for cyber devices.
SaMD requires particular attention to software lifecycle management, cybersecurity, usability, interoperability, clinical evidence, change management and post-market monitoring throughout the product lifecycle.
AI-enabled medical devices require additional attention to considerations such as data quality and representativeness, bias, model validation and clinical performance, human oversight, model changes, and post-market monitoring. In the EU, AI-enabled medical devices are regulated under the MDR/IVDR, with the EU AI Act introducing additional requirements for qualifying high-risk AI systems and an evolving framework intended to coordinate these requirements and avoid duplication. In the US, FDA emphasizes a total product lifecycle approach to AI-enabled devices and has established a Predetermined Change Control Plan (PCCP) framework that can facilitate certain planned modifications without requiring a new marketing submission for each change.